MacBook security alert: Update to macOS 11.3 right now

macOS 11.3
(Image credit: Shutterstock)

Apple macOS users are being urged to update their Macs to ensure they're protected against a zero-day vulnerability that’s been exploited by attackers since at least January. 

The flaw lets hackers bypass a whole suite of macOS security protocols, allowing them to deploy malware on affected machines. It may be one of the worst vulnerabilities to hit Apple’s computers in many years. 

Security researcher Cedric Owens identified the security bug back in March and noted it affects “all recent versions of macOS,” including macOS versions 10.15 Catalina, released in October 2019, to 11.2 Big Sur. 

Normally, macOS security mechanisms like Gatekeeper and File Quarantine would block malicious or unsigned files and software from being installed on Macs. But Owens found that this zero-day flaw allowed these obstacles to be bypassed, letting him craft malicious files that, when clicked on, didn't throw up a security alert in macOS and would run. 

Owens attributes this to the system miscategorizing the malware because of a logic error in macOS’ code, which creates a workaround to Apple's defenses. 

Apps as an avenue of attack

As we’ve before, such "Trojan" apps that appear benign play a key role in letting malware snatch the keys to your machine.

We've seen seemingly innocuous kids' apps harboring crypto-casinos on the App Store, not to mention recent news of a fake Netflix app spreading malware on Android phones

The point is: Apps are attractive to crooks as they often provide an easy entry point to exploit users' machines if they can convince a user to download or run an app that's not in the App Store, or is nestled between other App Store apps to appear legitimate. That's where built-in security measures come into effect, basically protecting users from themselves. 

Malicious mock-up

(Image credit: cedowens.medium.com)

On this occasion, Owens found that Gatekeeper failed to properly check specific scripts within apps. He used a tool called Appify, which had circumvented Gatekeeper checks all the way back in 2011 and offers a legitimate tool to enable developers to create basic apps with just a script.

With knowledge of these previous vulnerabilities in tow, Owens mocked up a test program to hide a harmless-looking document that concealed malware.

Owens was able to sail past up-to-date macOS software, even with Gatekeeper cranked up to its most stringent security settings. No warnings were triggered and the malware snuck past Apple's defenses to provide Owens with remote control over the Mac.

Here's a tweet by Mac security researcher Patrick Wardle with an animated GIF showing the attack in action. The calculator app popping up means a remote attacker has taken full control of the machine. (Wardle also wrote an in-depth blog post about how the flaw can be abused.)

Update macOS right now

Owens quickly informed Apple of the bug. Cupertino yesterday (April 26) released macOS Big Sur 11.3 with a patch to squash the bug, along with several other fixes.

The new ‌‌‌‌macOS Big Sur‌‌‌ 11.3 update can be freely downloaded on all eligible Macs using the Software Update section of System Preferences. 

If you use a macOS machine then we suggest you update it as soon as possible. It's particularly important as the zero-day flaw is actively being exploited.  

Actively exploited bug

It tends to be the case that zero-day flaws are discovered and patched before they're exploited. But in this case the bug has been harnessed by hacklers.  

Security firm Jamf Protect reported that the flaw has been actively exploited since January 9, 2021. Shlayer, an infamous piece of macOS malware, was the preferred route of attack by cyber-attackers using the zero-day vulnerability.

Jamf's security teams observed the "exploit being used in the wild by a variant of the Shlayer adware dropper." 

Like most avenues of attack that deliver adware payloads, the malware was deployed to earn money for crooks through fake clicks and bogus advertisement views. 

Despite the findings from the research, it's still unclear just how many machines were affected overall, and it shows just how quickly hackers can and will capitalize on exploits in the wild to earn money. 

The advice, as always, is to never download anything from untrusted sources and always ensure your system is up-to-date with the latest OS version. But even then, it's not always enough to deter a sophisticated and determined hacker intent on pillaging access to your system.

More: Chrome and Edge hacked by new zero-day flaw — what to do

TOPICS
Luke Wilson

Luke is a Trainee News Writer at T3 and contributor to Tom's Guide, having graduated from the DMU/Channel 4 Journalism School with an MA in Investigative Journalism. Before switching careers, he worked for Mindshare WW. When not indoors messing around with gadgets, he's a disc golf enthusiast, keen jogger, and fond of all things outdoors.

Read more
iPhone 16 Pro shown held in hand
Apple just patched its first zero-day flaw of the year — update your iPhone and Mac right now
Apple iPhone 16 Plus Review.
Apple just released an emergency security update for a flaw used in an ‘extremely sophisticated attack’ — update your devices right now
Apple iPhone 16 held in the hand.
iOS 18.3.1 — update your iPhone right now to fix critical zero-day vulnerability
MacBook Pro 16-inch 2021 sitting on a patio table
Critical macOS flaw puts your data and cameras at risk — update right now
MacBook Pro 2021 (16-inch) on a patio table
Macs under attack from dangerous malware targeting digital wallets and Apple’s Notes app — how to stay safe
Malware
New macOS malware uses Apple's own code to quietly steal credentials and personal data — how to stay safe
Latest in macOS
Mac Studio on a desk hooked up to a Studio DIsplay
Mac Studio M3 Ultra: 3 reasons to buy and 2 reasons to skip
Cyberpunk 2077 on MacBook Pro
5 great cloud gaming services for Mac that you should try right now
MacBook Prime Day
The widget you've always wanted comes to your Mac menu bar in Sequoia 15.2
Apple Magic Mouse USB-C
USB-C Mac accessories don't work with older macOS versions — this is a huge pain
How to keep to keep iCloud Drive files downloaded on your Mac
How to keep to keep iCloud Drive files downloaded on your Mac
How to access your passwords from the menu bar in macOS Sequoia
MacOS Sequoia lets you view saved passwords via the menu bar — here's how
Latest in News
Rendered images of rumored foldable iPhone.
Foldable iPhone report just revealed key details — here's what we know
NYTimes Connections
NYT Connections today hints and answers — Saturday, March 23 (#651)
NYT Strands on a cellphone
NYT Strands today — hints, spangram and answers for game #385 (Sunday, March 23 2025)
Nintendo Switch 2
Nintendo Switch 2 rumored specs — here’s what we know so far
iPhone 17 Pro render
iPhone 17 Pro — 7 biggest rumored upgrades
CAD renderings of the Google Pixel 10 Pro XL
Pixel 10 leak could be good news for all Android phones